Privacy Policy
Effective: 22 September 2026 · Last updated: 23 September 2026
Controller: Strimium SRL, MD-2003, mun. Chișinău, or. Durlești, str-la 4 Nicolae Testemițanu, 17, Republic of Moldova (IDNO 1019600057092), operating the service legivel at legivel.com. Contact: support@legivel.com.
Representatives in the EU and the UK (Article 27 GDPR / UK GDPR): We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:
- European Union (EU)
- United Kingdom (UK)
Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter or make use of your data subject rights, please visit the following website: https://app.prighter.com/portal/legivel
We apply the EU General Data Protection Regulation (GDPR), the UK GDPR and, as a company established in Moldova, Moldovan Law No. 195/2024 on personal data protection.
The short version
- Your documents are never stored. Markdown you submit and PDFs we generate are processed in memory and discarded when your request is served. They are not written to disk, to our database, or to our logs, and they are not in our backups.
- We store the minimum needed to run your account: email, name, hashed API keys, plan and usage records.
- We do not sell personal data, and no analytics run before you consent.
Who is responsible for what
We are the controller for account, billing, website, support and security data.
For the documents you submit:
- if you use the service for a business and your documents contain personal data of other people, we process that data on your behalf as your processor, under our Data Processing Agreement; you are the controller;
- if you convert your own documents in a personal capacity, we process them as controller, only to serve your request.
1. Data we process, and why
1.1 Documents you convert
Documents (Markdown in, PDF out) are processed in memory only and never stored. Our logs and usage records keep sizes, page counts, timings, error codes and opaque identifiers — never document content. If you use an idempotency key to make a request repeatable, you send the full content again with the repeated request; we keep only a cryptographic hash of the request — from which the content cannot be recovered — to recognise the repetition. The example documents shown on our website are our own content, not customer documents.
Legal basis: performance of the contract (Art 6(1)(b) GDPR).
1.2 Network delivery and protection
All traffic to legivel.com and api.legivel.com passes through Cloudflare, which terminates the encrypted connection at its edge and re-encrypts it to our server. Cloudflare therefore processes request data — including your IP address and, in transit, the content of documents you submit — as our sub-processor, to deliver the service and protect it against attacks. Our own dedicated request records omit IP addresses by design (see 1.5), and we keep no web-server access log of our own; only Cloudflare keeps edge logs on its side.
Legal basis: performance of the contract; legitimate interest in the security of the service (Art 6(1)(f)).
1.3 Remote resources referenced in documents
If your document references remote resources (for example images by URL), we fetch them only on your instruction, hold them in memory for that one conversion, and store none of them. For each conversion that fetched remote resources we keep, for 90 days, a fetch id, the account, counts and sizes — never the addresses fetched. The fetch runs from our own server; no additional sub-processor is involved.
Legal basis: performance of the contract; legitimate interest in abuse prevention (Art 6(1)(f)).
1.4 Account data
For registered accounts we process: email address (as typed, plus a normalised form used to detect duplicate signups), name, password hash or your Google/GitHub sign-in identity, email verification state, plan, and account settings. API keys are stored hashed; we can never show a key again after creation. When you sign in, the session records the IP address and browser identifier from which it was created, so that you can recognise and revoke your sessions; the record lives as long as the session and is deleted when the session ends (sessions expire after 30 days without use and are then removed; IPv6 addresses are recorded truncated to their /64 network). This data is needed to conclude and perform the contract; without it we cannot provide an account.
Legal basis: performance of the contract.
1.5 Usage records and technical logs
We record, per conversion: sizes, page counts, timings, outcome and error codes, under opaque identifiers — used for metering, plan limits, troubleshooting and abuse prevention. Our request records — one row per call, with time, route, status, timing, sizes, error code and opaque identifiers — contain no IP addresses and no document content and are kept for 90 days.
Legal basis: performance of the contract; legitimate interest in service integrity.
1.6 Guest use, signup and abuse prevention
If you use the editor without an account, we process your IP address to apply the guest limits; those counters are held in memory for the current limit window (at most one hour) and are not written to disk. At signup we process your IP address (kept 30 days, then cleared), a Cloudflare Turnstile bot check, and a check of the email domain against a list of disposable-email providers. Signups per IP address are counted per day. Nothing is blocked automatically on suspicion; blocking an account is a human decision.
Legal basis: legitimate interest in preventing abuse of the free offer (Art 6(1)(f)).
1.7 Stored seal certificates (optional, paid plans)
If you store a certificate with us for sealing PDFs: the certificate bundle is encrypted at rest together with its password; its public metadata (subject name, expiry) is kept readable and shown on your account page; and we record your authorisation sentence with a version and timestamp. You can delete a stored certificate at any time. Every sealed document is logged by certificate fingerprint and document hash — never document content — so that it can later be established which certificate sealed which document. Certificate material sent inline with a single request is used in memory for that request and wiped; it is never written to disk, database or logs.
Legal basis: performance of the contract, including your authorisation to seal on your behalf; legitimate interest in being able to evidence sealing operations.
1.8 Billing
Subscriptions are sold by our payment provider as merchant of record; the provider processes your payment and card data as an independent controller under its own privacy policy. We receive and store subscription status, invoices and billing events — not card data. Provider payloads we receive are minimised after 90 days.
Legal basis: performance of the contract; legal obligation for accounting records (Art 6(1)(c)).
1.9 Email
We send transactional email (verification, receipts and usage notices, certificate expiry, security notices) through Resend from the domain mail.legivel.com. Our support and abuse mailboxes are hosted on Google Workspace. Lifecycle and product emails beyond transactional ones carry an unsubscribe link.
Legal basis: performance of the contract; legitimate interest or consent for non-transactional email.
1.10 Support and abuse reports
If you write to support@legivel.com or report@legivel.com we process your message and address to answer it.
Legal basis: legitimate interest in operating support and handling abuse.
1.11 Website analytics
Google Analytics 4 (via Google Tag Manager, Consent Mode v2) runs only after your consent — see the Cookie Policy. Google processes this data on our behalf. Our own product metrics are collected server-side and cookie-free, without personal identifiers.
Legal basis: consent (Art 6(1)(a)).
We make no decisions based solely on automated processing that produce legal or similarly significant effects for you.
2. Retention
| Data | Retention |
|---|---|
| Documents (Markdown, PDF) | never stored |
| Request hash for repeatable requests | 24 hours |
| Request records and their log copies (no IP addresses, no content) | 90 days |
| Remote-resource fetch records (id, counts, sizes) | 90 days |
| Signup IP address | 30 days |
| Sign-in session records (creation IP address, browser) | life of the session; deleted at sign-out, and expired sessions are removed daily |
| Guest-limit IP counters | in memory only, at most one hour |
| Seal log (certificate fingerprint, document hash) | while the account exists; after deletion, see below |
| Payment-provider payloads | minimised after 90 days |
| Subscription and billing mirror records | duration of the subscription + 24 months |
| Accounting records (provider payout statements, invoices we issue) | 6 years from 1 January of the year after the record is finalised; longer while a dispute about it is pending |
| Encrypted database backups | 30 days |
Backups. We keep encrypted backups of our database for 30 days, for disaster recovery only. Backups contain account data, never your documents — documents are not stored anywhere. When you delete data or your account, the deletion takes effect immediately in the live system; copies may remain inside encrypted backups for up to 30 days, until those backups expire. If we ever restore from a backup, we re-apply every deletion made after that backup was taken, so deleted data does not come back. For this purpose we keep a list of deletions for as long as the backups it refers to exist. The same applies to data we clear on a schedule, such as IP addresses: a cleared value can persist inside encrypted backups for up to 30 days.
After account deletion. When you delete your account we immediately remove your profile (email, name, sign-in identities), your API keys and any stored seal certificates. We retain:
- usage records, under an identifier that is no longer linked to your account, for 13 months;
- the seal log, under an identifier that is no longer linked to your account, for 13 months, so that sealing operations can still be evidenced;
- accounting records, for the statutory term shown above;
- administrative audit entries, which never contain names, emails or IP addresses.
Your sign-in sessions, including their IP records, are deleted together with the account. While a paid subscription is active, deletion is refused: cancel the subscription first — you keep access until the end of the paid period — and delete afterwards.
3. Recipients
We use the providers listed on the Sub-processors page, some as our processors and some as independent controllers. We disclose personal data to authorities only where legally required.
4. International transfers
Our servers are located in Falkenstein, Germany (Hetzner), with encrypted backups on Hetzner storage in Helsinki, Finland — both in the EU. Strimium SRL is established in the Republic of Moldova, and authorised staff access account data from Moldova. Moldova is not the subject of an EU or UK adequacy decision; where our access from Moldova is a transfer requiring safeguards, we rely on the EU Standard Contractual Clauses and the UK Addendum, as set out in the Data Processing Agreement. Where our providers process data outside the EEA or the UK, the safeguard for each is listed on the Sub-processors page.
5. Your rights
You have the right to access, rectify and erase your personal data, to restrict its processing, to data portability, and to withdraw consent at any time where processing is based on consent. Write to support@legivel.com; account deletion is also available on your account page or by email (see §2). We answer within one month.
Right to object. Where we process your data on the basis of legitimate interests (sections 1.2, 1.3, 1.5, 1.6, 1.7, 1.9 and 1.10), you may object at any time on grounds relating to your particular situation. You may object to non-transactional email at any time, without giving reasons.
You may lodge a complaint with a data-protection authority — in the EU, the supervisory authority of your member state; in the UK, the Information Commissioner's Office; in Moldova, the National Centre for Personal Data Protection (CNPDCP).
6. Security
Documents are processed in memory and never persisted. Transport is encrypted (TLS). Stored seal certificates are encrypted at rest with versioned keys. Backups are encrypted. Access to production systems is restricted to named administrators using key-based authentication, and administrative actions are audited without personal data in the audit trail.
7. Children
The service is not directed at children. You must be at least 18 years old to hold an account.
8. Changes
We will announce material changes to this policy by email to account holders and by a notice on the site before they take effect.